# CISM interview scorecard

Candidate: ______  Interviewer: ______  Date: ______

| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you align our security strategy with the business strategy? | Start from business objectives and risk appetite, turn them into security objectives, assign governance roles, and report in terms the board uses. | |
| 2 | Who should own the information security policy, and who approves it? | Senior management owns it, the security function drafts and maintains it, an executive body approves it, and it is reviewed on a set cycle. | |
| 3 | How would you run our first information risk assessment? | Assets with named owners, threats and vulnerabilities, likelihood and impact, a risk register, and treatment within the risk appetite. | |
| 4 | A business unit wants to accept a high risk. What do you do? | Make sure an owner with the authority accepts it in writing, for a set period, within appetite, or escalate it. | |
| 5 | How would you build a security program from scratch? | A gap assessment against a framework, a roadmap with budget and people, early wins, and measures from day one. | |
| 6 | How do you show the program is working? | Measures tied to objectives, trends over time, and reports that lead to decisions, not raw counts. | |
| 7 | Walk me through the first hour of an incident. | Triage and classify, activate the plan and roles, escalate, communicate, preserve evidence, and check legal and regulatory notice duties. | |
| 8 | How do you know we are ready for an incident? | Tabletop and technical exercises on a schedule, and lessons learned that change the plan. | |

Source: https://credentialpress.com/guides/cism-interview-questions
